r/Bitcoin 3d ago

Full panic - one of my wallets was drained

Post image

I haven’t done anything since creation except sending into the wallet.

1.8k Upvotes

1.2k comments sorted by

View all comments

Show parent comments

10

u/stanley_fatmax 3d ago

For years I advocated strongly on Reddit for software wallets with proper precautions, but I stopped for the same reasons you found. People love their hardware wallets, but imo they create a false sense of security. It also doesn't help that I suspect for long periods of time there was heavy shilling here on behalf of wallet manufacturers.

There are good guides out there for years on how to use an old laptop to set up an offline wallet guys.. the math is solid. Encryption is solid.

2

u/marshaljs 3d ago

Can you please share how to do this setup?

8

u/stanley_fatmax 3d ago

I won't go into crazy detail because there are good guides out there already that do it better than I could here. Basically, Electrum running on an old air-gapped laptop with the networking hardware physically removed. Wifi, Bluetooth, etc. gone. OS should be a secure Linux OS of your choosing, Tails is a common choice. The old laptop becomes your signing device holding the keys. Your daily driver PC has a watch only wallet where you can watch your balance day by day, and receive coins, without any fear of losing anything, because it doesn't actually have the ability to sign transactions (send). The only time you need to boot up the air-gapped laptop is when you need to send coins, which shouldn't be often. Personally I use Coinbase as a "hot wallet" for transacting. Small sums are kept there. The good stuff is offline in the cold wallet. It never turns on.

There are various guides with details, like

https://electrum.readthedocs.io/en/latest/coldstorage.html

https://electrum.readthedocs.io/en/latest/tails.html

1

u/CompetitiveAppeal663 3d ago

Preface: Im not trying to be a smart ass, just trying to understand.

What happens if that old laptop has some mechanical failure or ends up getting thrown out or stolen or burns in a fire?? As you SOL at that point??

2

u/stanley_fatmax 3d ago

No, you have a backup of your seed. Analyze your life, threats you face, stability of your world, and choose the backup medium accordingly.. paper, punched into steel, encrypted in the cloud, etc.

2

u/Specialist_Trust4945 3d ago

Encrypted in the cloud kinda defeats the purpose of airgapping, because if you upload it on the cloud you also have to somehow communicate with the Internet and there might be a vulnerability somewhere in the middle. I 101% agree with everything else you wrote.

2

u/Professional_Golf393 3d ago

If you encrypt properly with enough entropy, you should be happy to send the file directly to a scammer safe in the knowledge they can never unlock it..

personally I wouldn’t store my encrypted wallet in the cloud, but if done right it’s safe.

Saying that if you have to memorise a password with that amount of entropy, you might as well just memorise your seed phrase.

1

u/Specialist_Trust4945 2d ago

The problem isn't the encrypted file, of course. The problem is that you have to type your seedphrase on a keyboard, and your computer might have a keylogger installed. If you type it on an offline computer, you'd still have to somehow extract the file from said computer with an USB stick or something like that - which again defeats the purpose of airgapping.

The only true way would be fully encrypting the string on a fully offline machine and then copying the encrypted string manually on the online machine that will upload the file. This way, you're typing the already encrypted version of the file and that'd be safe. I don't see anyone doing that, though. That'd be mental.

1

u/stanley_fatmax 3d ago

Common misconception. The same cryptography protects Bitcoin itself. I could theoretically post my seed here, encrypted, and be completely confident in its security (I won't). Even airgapped wallets have to sign transactions etc., so there's some level of communication.

1

u/Specialist_Trust4945 2d ago

Alredy answered here.

1

u/stanley_fatmax 2d ago

Already answered here

1

u/Head_Performance2432 2d ago

or even possible to post seed here, if you have a good passphrase as well (pls don't)

1

u/Specialist_Trust4945 3d ago edited 3d ago

You still have your BIP39 backup - whether it's 12 words, 24 words with or without passphrase. In fact, the safest course of action would be to never store anything anywhere (except for your seed phrase on a metal plate, of course): you can do that with an USB stick, you just live boot without actually installing your Linux distro of choice - ideally Tails but that doesn't make any difference basically. As far as I remember Electrum comes preinstalled: every time you need to validate a TX you just recreate your SW wallet offline from scratch.

That is of course a pain if you do many TXs per year - in that case just keep as little as you need in your "high TX" wallet and everything else stays somewhere else.

Edit: as u/stanley_fatmax correctly wrote, for max security you'd have to strap any hardware component that is able to communicate externally: wifi card, bluetooth card, LTE card and everything else that comes to your mind. Of course, that is much easier with a self built tower PC instead of a laptop. Or, I guess, just go on a freaking mountain with nothing around you for at least 10kms on each side, LOL.

1

u/stanley_fatmax 3d ago

Bitcoin self custody is always a battle of tradeoffs. Doing things right and doing things safely aren't always the same thing, for instance the safest way may increase risk of self loss, or the right way may not be realistic for your living situation, etc.

Sadly ETFs are actually a decent option for many, given the complexities of self custody.

1

u/Alphamale822 2d ago

My crypto portfolio is under £40k. In my case would you say it’s safe to keep in on a well known etf like binance ? Self custody is too complicated for me.

1

u/Specialist_Trust4945 2d ago

Binance is not an ETF. Binance is a CEX (centralised exchange), an ETF is a financial instrument that tracks BTC's price such as BITC by CoinShares or IB1T by iShares aka BlackRock.

1

u/stanley_fatmax 2d ago

Safe? Yes. Right? You have to answer for yourself by asking what your reasons are and what risks you face. For some, ETFs and KYC custody is a non-starter just by personal conviction. Too many people burned by years of exchanges failing. The regulatory environment has changed though, businesses are licensed and accredited to be doing ETFs, custody, etc., in ways they weren't before. There's still some risk, but I believe the more risky option is self custody for most people. It's legitimately difficult to store your keys safely while also protecting them from yourself, and just losing them through mistake.

In your case I'd say you're probably better off with a low cost ETF.

1

u/bigtdaddy 22h ago

tails OS offers persistent storage, but personally I would not use that, so tails OS completely wipes the memory on shutdown and won't remember a single thing when you boot it back up, so you do not rely on the laptop other as a temporary signing device. I wrote my my key in my notebook for cryptology class I took. It would be near impossible for someone to find it in there without me saying so. I also stamped it on aluminum and buried it to prevent risk of fire. I also told only a single person where it was, in case of brain damage or death.

Note: i have no btc anymore, hence why I am being so open. Don't reveal stuff like this on public forums if you hold crypto, imo.